A colleague pings you at 4pm. They have a spreadsheet of customer accounts, a question they can’t answer by staring at it, and an AI tool open in the next window. They ask you — because you’re the one who seems to know about this stuff — “can I just paste this in?”
Whatever you answer in the next thirty seconds becomes your company’s data policy. That’s how most of them actually get written.
So let’s give you a better answer than “um, probably not?”, because the reflexive no has a cost people underestimate. A blanket ban doesn’t stop people using AI. It stops them telling you they’re using AI — on personal accounts, on their phones, with no logging, no approved tier, and no rules. Shadow usage is the outcome you’re actually choosing when you choose “never.”
The three questions hiding inside the one question
“Is this safe?” is unanswerable because it’s three different questions bundled together, each with a different answer and a different person responsible for it. Pull them apart and the fog lifts immediately.
1. Will it be used to train the model? A technical/contractual question about the vendor. Answered by the terms of your specific plan.
2. Who can see it, and for how long? A question about retention, staff access, logging, and where the data physically sits. Also answered by the vendor’s terms — but a different section, and people constantly conflate the two. “They don’t train on it” does not mean “nobody stores it.”
3. Are we allowed to send it to a third party at all? A question about your obligations — customer contracts, NDAs, regulation, sector rules. This one has nothing to do with the AI vendor. It’s the same question you’d ask about any new supplier, and it’s the one that most often actually bites.
Most arguments about AI and data are two people answering different questions at each other. Name which of the three you’re on and the conversation gets short.
The variable that matters more than everything else: which account
Before any policy, any tiering, any redaction habit — settle this one thing.
Consumer accounts and business accounts are governed by different terms. They frequently differ on training, on retention, on admin visibility, on logging, and on whether your company has any contractual relationship with the vendor at all. Two people at the same company doing the identical task, one on a personal login and one on a company seat, are in completely different legal positions.
Do not take this guide’s word — or any guide’s word — for what your plan does. Guides go stale; terms change. Do this instead, once, and write down what you find:
- Open the terms for the exact plan your company pays for, not the marketing page.
- Find the section on whether inputs are used for model training. Copy the sentence.
- Find the section on retention — how long, and who at the vendor can access it under what conditions. Copy that sentence too.
- Check your admin console for the settings that control any of this, and confirm what they’re set to.
- Put those two sentences and that setting into a shared document with the date.
That document ends the recurring debate permanently, and it’s the foundation everything below sits on. Ten minutes, once.
The four-tier ladder
Now the actual working rule. Blanket answers fail because the question isn’t binary — a public press release and a payroll file are not the same object. Almost every team that gets this right ends up with some version of four tiers.
Tier 1 — Public. Anything already published or publishable: your website copy, public pricing, published reports, industry material. Rule: no restrictions. Use AI on this freely. Most people’s most useful work lives here and they don’t realize it.
Tier 2 — Internal, non-personal. Draft documents, internal processes, anonymized numbers, meeting notes without sensitive personnel content, templates, strategy that isn’t market-moving. Rule: fine on an approved company account. This is where the majority of real productivity gain sits, and it’s the tier people wrongly treat as forbidden.
Tier 3 — Confidential or personal. Named customers, employee records, salaries, health information, unreleased financials, anything under an NDA, anything identifying an individual. Rule: only on an approved tier, and only redacted or with an explicit approval. Note that “we have an enterprise plan” answers question 1 and 2 but not question 3 — the client contract still gets its own look.
Tier 4 — Regulated or contractually fenced. Payment card data, national ID numbers, regulated financial or medical records, anything where a specific law or a specific client contract names how it may be processed. Rule: not without a documented, signed decision. This is not a judgment call for an individual at 4pm on a Thursday.
The reason four tiers works when a ban doesn’t: it tells people what they can do. A policy that only says no gets ignored. A policy that says “tiers 1 and 2, go wild, no permission needed” gets read, because it gives something away.
Redaction is a habit, not a policy
The single most useful individual skill here is boring: getting good at removing identifying detail without removing the problem.
Almost every Tier 3 question has a Tier 2 version that’s just as useful:
- “Here are our 200 customers with names and revenue — find the churn pattern” → replace names with
Customer 1..200. The pattern doesn’t live in the names. - “Review this contract with Acme Corp” → swap in
[CLIENT],[VENDOR],[AMOUNT]. The clause analysis is identical. - “Draft a performance conversation for Sara who is struggling with deadlines” → describe the situation, not the person.
Two rules keep this honest. Redact before you paste, not after — there’s no un-sending. And beware re-identification: “our largest client in Abu Dhabi in the logistics sector” is not anonymous just because you removed the name. If three details together identify someone, removing the name changed nothing.
Pasting into a chat vs. pointing a tool at a folder
A genuinely new question, now that desktop AI tools work on your actual files rather than on what you paste.
Pasting is a per-message decision. Its weakness is human: under time pressure, people paste the whole thing.
Opening a folder is a per-project decision, and it’s the stronger model if you treat the folder as the boundary. Tools like Claude Code Desktop only see the folder you point them at — which is a real control, not a comfort blanket, provided the folder is scoped deliberately. The failure mode is pointing it at a shared drive root because that’s where the file happened to live.
So the working habit is: make a folder for the task, put in it only what the task needs, and open that. As a side benefit, this also makes the AI better — a tool looking at four relevant files gives sharper answers than one wading through four hundred.
The other Desktop-native control worth knowing: permission prompts before anything consequential, and a visual diff you accept or reject before any change lands. Those are guardrails against a different risk than disclosure — accidental modification — but they’re part of why a Desktop-first rollout is easier to govern than handing everyone a chat window. Our Desktop rollout guide covers that side in more depth.
Regional and sector rules
If you’re operating in the UAE or the wider Gulf, your Tier 3 and Tier 4 lines are also shaped by local data-protection law and, in some sectors, by rules about where regulated data may be processed and stored. The same is true of European operations, healthcare anywhere, and anything touching payments.
Two honest points. First, this guide can’t tell you your obligations — jurisdiction, sector, and contract combine differently for every company, and anyone who gives you a confident universal answer is guessing. Second, and more useful: the residency and regulatory question is almost always a procurement question, not a per-employee question. It gets settled once, at the plan and contract level, by the people who sign contracts — and then everyone else just follows the tier rule. Don’t let an unanswered Tier 4 question hold up Tier 1 and Tier 2 usage for the whole company; they’re independent decisions. If you’re doing this rollout in a Gulf context, our UAE and Gulf teams guide covers the surrounding practicalities.
The five lines to publish this week
You do not need a thirty-page policy. You need something people can hold in their heads. Here’s a version to adapt:
- Use your company account. Not a personal one. Ever, for work.
- Public and internal material: go ahead. No approval needed. (Tiers 1–2.)
- Named people, customers, or NDA material: redact it, or ask first. (Tier 3.)
- Regulated data: never, without a written decision. (Tier 4.)
- You own the output. If it goes out with your name on it, you checked it.
That fifth line matters more than it looks — it connects the data question to the accuracy question, which is the other half of using this stuff responsibly. (Why AI makes things up is the companion piece.) And if you want the fuller version — accountability, disclosure, tool approval, and how to roll it out without killing adoption — that’s the subject of your team’s first AI ground rules.
The real risk
Most teams spend their worry on the wrong risk. The imagined disaster is a dramatic leak of confidential material into a training set. That’s worth guarding against, and the five lines above guard against it.
The far more common actual outcome is quieter and more corrosive: a company where AI is technically banned, universally used, and never discussed. No approved tier, no logging, no tiering, no shared habits, and nobody who can ask “should this have gone in there?” because officially none of it is happening.
Publishing a real rule — one that says yes to most things — is the intervention that fixes that. It’s also, not coincidentally, the one that lets the productivity gain actually show up on your side of the ledger.